PSTrayFactory.exe

PS Tray Factory

PS Soft Lab

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘TrayFactory’.
Publisher:
PS Soft Lab

Product:
PS Tray Factory

Version:
3.0.3.198

MD5:
d95c4f0265ce8d4ee33c867f95ecd62e

SHA-1:
f58dd64a005a8b1eb3daa20d7c4ba21cf3b55f5a

SHA-256:
3fd50e029fb0f7d6691f6dd6f42c67ec47e34515b1be96a2c054ccadd63b08d0

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
12/21/2025 11:36:01 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Bkav FE
W32.HfsAutoB
1.3.0.4959

Comodo Security
Heur.Suspicious
17357

File size:
1.2 MB (1,304,576 bytes)

Product version:
3.0

Copyright:
Copyright (C) 1998-2009 by PS Soft Lab

Original file name:
PSTrayFactory.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\ps tray factory\pstrayfactory.exe

File PE Metadata
OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:i0lrB8JJHAEqTqAxZu/sFfmSDeEbAlKy1e:iQrKJqeADNpeE0lKy1e

Entry address:
0xD4740

Entry point:
55, 8B, EC, B9, 2F, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, 53, 56, 57, B8, C8, 43, 4D, 00, E8, 3F, 22, F3, FF, 33, C0, 55, 68, AF, 52, 4D, 00, 64, FF, 30, 64, 89, 20, 8D, 55, EC, B8, 01, 00, 00, 00, E8, C4, E1, F2, FF, 8B, 45, EC, 8D, 55, F0, E8, 89, 41, F3, FF, 8B, 45, F0, 50, 8D, 55, E8, B8, C8, 52, 4D, 00, E8, 78, 41, F3, FF, 8B, 55, E8, 58, E8, 13, F8, F2, FF, 75, 61, A1, 04, 80, 4D, 00, 8B, 00, E8, F5, F6, F2, FF, 85, C0, 0F, 8E, DE, 0A, 00, 00, C7, 05, F4, 9F, 4D, 00, 01, 00, 00, 00, A1, 04, 80...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
849.5 KB (869,888 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
TrayFactory

Command:
C:\Program Files\ps tray factory\pstrayfactory.exe \start


Scan PSTrayFactory.exe - Powered by Reason Core Security